8 ms·
Web Security is Too Hard
- deleted 2mo ago[deleted]
- TZubiri 2mo agothis from a company whose main product is (was) security. I feel there's a generalized decrease in quality in software in general.
- 63stack 2mo agoMy main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
- madeofpalk 2mo agoThe takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations. GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on. Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
- InsideOutSanta 2mo agoFricken Proton has a separate domain that lists all of their apps, https://protonapps.com/ https://protonapps.com/. This absolutely screams "scam", but no, it's real. Ffs, just put this on apps.proton.me or something so I actually know it's real!
- inigyou 2mo agoOnce upon a time, RuneScape ran a promotion where World of Warcraft players could join a special world with double XP (experience points) or something by clicking this promotion link. RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...
- Joker_vD 2mo agoAnother entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
- make3 2mo agothis is the correct take
- derektank 2mo agoYou really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains
- nerdsniper 2mo agoRunning marketing off a separate domain is often a conscious decision because if they start getting blocked for spam, then critical service/operational emails from your actual domain might also get blocked.
- saghm 2mo agoOh good, I'm glad that Cloudflare, proud defender of internet security, is properly focused on the important goal of optimizing for their ability to send promotional emails to my inbox rather than silly things like helping prevent phishing attacks.
- raesene9 2mo agoSame Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
- dwedge 2mo agoI guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
- dwedge 2mo agoI just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.
- Hovertruck 2mo agoDon't worry, I think everyone probably went on the same roller coaster with this one
- yellow_lead 2mo agoAt one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
- mirashii 2mo agoWhat’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
- wslh 2mo agoAnd as a dark pattern it adds "positive friction" for the company reducing the number of people that will have the motivation of obtaining the real people support.
- saghm 2mo agoSeveral weeks ago I had an issue not being able to login to Verizon's website, so I tried to chat with someone. The chatbot that was gatekeeping was predictably useless said it would redirect me to a human except...it kept prompting me to log in first. It was literally impossible to differentiate from if they literally had no humans online to talk to at all.
- sholladay 2mo ago> That human would have also been hopelessly uninformed for all the same reasons. Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering. In fact, they would have likely already heard about the new product at lunch or something.
- munk-a 2mo agoMost chat support people were contractors hired from third party companies that were given dossiers about their products that were often quite out of date because poor management has always been a thing.
- thataccount 2mo agoCloudflare is your favorite company and they are geniuses? Dear Diary, Today my fanboy bubble was burst. Signed, Author
- ericlaw 2mo agoNote that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.
- thataccount 2mo agoAnother company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.
- Panino 2mo agoI hadn't read that so I looked it up to verify, and it appears true: https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-dodge-responsibility-facilitating-human-rights-abuses-export https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-... Cisco looks to have made money from repression and torture. Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.
- robocat 2mo ago> sites are on Cloudflare And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house. Are Cloudflare supposed to be the police? Does the UN provide a registry list of criminal domains that should not be livened?
- inigyou 2mo agoDoesn't even matter who CF is hosting - the fact they're sending all our HTTP requests to the NSA should be enough reason already!
- thadt 2mo agoIn the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names. Identity is hard y'all.
- saghm 2mo agoI don't understand what your point is. Do you disagree with any of the concrete suggestions in the blog post about what should have been done differently, or do you think they're hard to follow?
- thadt 2mo agoThe blog’s suggestions are fine. I’m pointing out that this issue is less about “security” and more a problem of “identity”. And that such issues with identity are likely to increasingly be a problem.
- sghiassy 2mo agoJust use LLMs. They can apparently doing everything and all the things
- deleted 2mo ago[deleted]
- 1970-01-01 2mo agoThis isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
- marcta 2mo agoPresumably the big scary sysadmins have access to the *.cloudflare.com DNS records, and marketing just needs to push this thing right now and can't wait, so it's easier for them to buy a new domain with a shiny new TLD than wait for pay.cloudflare.com to be authorised. cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such a big company.
- hahahaa 2mo agoGoogle manages it though. And you could have a labs.cloudflare.com/idea and make it easy to add new ideas internally.
- nemothekid 2mo ago>Why is pay.cloudflare.com so hard to establish? An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc. > `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is blocked. I don't care that it's a Zig application. I remember just doing SOC2 for a startup and it made just spinning up an EC2 instance require several steps of rigamarole just to be "in-compliance". And if anything goes wrong? Well why didn't you follow the 2,000 step process? I don't envy anyone who has to deal with issues like these.
- frollogaston 2mo agoProbably half those problems are SOP/CORS, which gets in the way in exchange for a false sense of security. I'm on board with ditching that. Websockets already did. (Cookies should still adhere to SOP though.)
- epochbtc 2mo agoIronically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
- OkayPhysicist 2mo agoWhy is this so, so common? They're subdomains. They're free. It's not hitting anybody's budget to publish a new DNS entry. If someone has permission to publish anything in your name, they probably should be able to go make themselves a subdomain.
- epochbtc 2mo agoCounter-argument is: do you really want some team of 90% marketers and PMs throwing up a MVP/WIP codebase for some ancillary product not related to your core business on your core domain? At a minimum you'd want a thorough security review and risk assessment, and that goes against the ethos of "ship fast and pivot as needed".
- ryandrake 2mo agoWhy does the TLD matter in this case? How does your security/risk posture change if you launch on myexperiment.mycompany.com vs. www.mycompanyexperiment.website that you had to go out and newly purchase? Asking because I legit don't know.
- nvme0n1p1 2mo agoOne example: a subdomain like experiment.example.com can access cookies for example.com.
- saghm 2mo agoI mean, it sounds like they're already doing that, just with extra downside
- LocalH 2mo agoWeb security wasn't hard before we started trying to make the web a platform for full executable software. I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE). JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake. Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
- OkayPhysicist 2mo agoNone of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".
- LocalH 2mo agoJavaScript (and other forms of executing logic within the browser) have made the situation worse, though. To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
- saghm 2mo agoIf a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.
- LocalH 2mo agoBad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation. We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again. I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
- andremendes 2mo agoWhat a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.
- EGreg 2mo agoI only realized it wasnt after googling for the phrase “cloudflare.pay” and finding the announcement on Cloudflare’s own blog, which I trust because it is on cloudflare.com All the bots including Google’s say it’s a phishing scam site probably, since they don’t know Cloudflare has a wallet product.
- hahahaa 2mo agoI thought it wouldn't be as I assume :) CloudFlare scans for new tld and either gets in the sunrise period or at a minimum objects to anyone else registering a straight CloudFlare.tld. But CloudFlarepay.com or cl0udflar3.com have more scam risk.
- iryndin 2mo ago[dead]
- wackget 2mo ago1. Why is this website blocked when I try browsing it using Brave? 2. Why on earth would you want a financial product from a WAF?content delivery company?
- aDyslecticCrow 2mo agoYou didn't read the whole article; it's not a scam, it's a new official cloud-flare product.
- ozim 2mo agoWeb Developers, please follow every best practice, I’m begging you Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas. No one is asking Web Developers about their opinion man. STOP making everything developers fault.
- hahahaa 2mo agoWho do we call? CTOs I guess.
- Yizahi 2mo agoGhostbusters!
- inigyou 2mo agoWho made the website?
- technion 2mo agoDies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today. This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
- 12345ieee 2mo agoI had marketing close their godaddy account and centralized the domain request flow to the ops team, for security reason. One of the best workflow changes ever implemented, didn't even need to become CTO.
- ozim 2mo agoWho designed the customer flow? In TFA there is no single issue of actual things that web developers could be blamed for. CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords. All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.
- joemi 2mo agoIt looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.
- saghm 2mo agoI mean, what would stop someone from registering mycloudflare.pay and doing the same thing? Having the link in the other direction seems like what matters more
- Joker_vD 2mo agoBy "the same thing", you mean writing the blog post on Cloudflare's official blog?
- inigyou 2mo agoNo, they mean making it link to the blog.
- joemi 2mo agoI mentioned it because the blog post itself links back to cloudflare.pay. Of course just linking to a blog post is useless.
- EdwardDiego 2mo agoYou should've mentioned that in your original comment because it changes the meaning of it entirely.
- joemi 2mo agoI assumed that the fact the blog post verified the legitimacy was implied, or that people would look at it before commenting if they didn't think it was implied. My bad.
- 2mo ago
- aprilnya 2mo agoI saw the whole Cloudflare Pay thing and had the exact same thoughts - this has to be some sort of phishing...
- ernsheong 2mo agoCloudflare seems to be trying to do EVERYTHING.
- inigyou 2mo agoEvery company has to try to do everything, before any other company does, especially related ones. It's why Valve moved into OSes and hardware. If they didn't, Microsoft were holding a nuclear bomb over their heads. It's why Google has a phone platform, because Apple has been replacing the Google apps one-by-one. It's also why Samsung has a parallel suite of apps to the Google ones. It's why the pizzeria makes fries, because they're threatened by the fry shop across the street starting to serve pizza. It's why Uber tried to make self driving taxis. It would be good if the fry shop made only the best fries and the pizza shop made only the best pizza and Valve made only the best game store and Microsoft made only the best OS, but it's a very unstable equilibrium. Does your ISP still give you an email address?
- stymaar 2mo agoSo it's not just FedEx[1] who does that, but also one of the most important tech company… [1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-getting-phished/ https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
- tchalla 2mo agoI tried to signup and got an "Internal Server Error" post the auth callback. Embarrassing for Cloudflare. Par for the vibe coded culture I guess.
- tailscaler2026 2mo ago[dead]
- Insimwytim 2mo agoThe Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…). That's just gold
- j45 2mo agoDepending on how possible it is for a use case, reducing the attack surfaces and vectors can help, such as being mindful of how much client side javascript exposes anything.
- eaf7e281 2mo agoI also immediately check to see if it's an actual Cloudflare product because cloudflare[.]pay seems too suspicious to me. Luckily, Google didn't fail me this time. Found a blog about this product with a link to the same domain.
- saadyousfi 2mo ago[flagged]
- varenc 2mo agoCosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
- lee_ars 2mo agoYou'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled. The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either. The domain's whois is also devoid of identifying details: https://rdap.nominet.uk/pay/domain/cloudflare.pay https://rdap.nominet.uk/pay/domain/cloudflare.pay Registered through 101domain, with nothing except a registrar abuse contact. I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck. edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.
- varenc 2mo agohah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it. Makes sense it's not helpful, alas.
- frollogaston 2mo agoHow would that association be shown to the user? Currently we're trained to check that the domain name is the same.
- pjmlp 2mo agoSecurity in general is hard. It starts on developers own machines, which programming languages get used, how dependencies are added to the projects, how testing is done, how code gets written, how inputs and current user roles get validated. All of this before even exposing the application to a BSD socket.